Sign inSign up
Docker Sandboxes Agent Templates

dhi.io/sbx-templates

Docker SBX Agent Templates (Codex) (docker, dev)

CIS
linux/amd64
debian 13
Tags:

codex-0-docker, codex-0.155-docker, codex-0.155.0-docker, codex-docker

Index digest:

sha256:e67bc3cae6fce8d3f791612e6efc516e3076b0efe0d37b20eeab1d7a98e1b268

Manifest digest:

sha256:2d5ab1c7ce88e3a3d48b3c083dfdb30b5aab1d54c45dd43e44bb64c928972ad6

Size

586.55 MB

Last pushed

3 hours ago

Vulnerabilities

0
1
6
41
5

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/sbx-templates:codex-0-docker

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/sbx-templates:codex-0-docker --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/sbx-templates@sha256:b1567c7e38ccb6d17fcda993ae1f7d666f781198a7acf2c39a2c28e0f378c830
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/sbx-templates@sha256:a9de944682e0d8046fd14edaf4facaf1ed4f51c5b3e6c5b863396a488d879feb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/sbx-templates@sha256:85b663bb884c180f41a33611aedc5e21e24d2072c7be09cb38984eb94161f548
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/sbx-templates@sha256:d497688caa1a7b8323bf2f0ce0dbc9e87deed5ff029500028fb72022c3875c87
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/sbx-templates@sha256:b10e2820800d10ddef981853f5797587384912971b58c2785faa41279593dccc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/sbx-templates@sha256:8d4503718f7c324d4d6f514a54ec642b88bbd0b417c1cf1efd82f96b9ff0c329
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/sbx-templates@sha256:dee72bd4b553744971b2a1e5fe7d0105d3223b36230d37cf213dc8493ace00b9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/sbx-templates@sha256:0e0afe1c807dda2fae54a1e64c4cd46397fc59ead3125a008b0b3a5ef7ab671e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/sbx-templates@sha256:cbae8d603283deee240aa0acd96a3492f1a13f8da8606bec4701d2b0515dcce9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/sbx-templates@sha256:7eba4d5574b725b28cea1dc31ef5514d7ac82dcd28c69e3753ebe9bf2b8fb927
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/sbx-templates@sha256:f843cee6e8b773d7663b7fc2489e67522dbcddb246d8f7d534e5356bf39e72c9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/sbx-templates@sha256:47dc2cd27c4b40473f2efd43897d85a36c8d29218f9fd2c726de5e6cfe726a34
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/sbx-templates@sha256:e6f2bbf53c1af5d8d61fe369426fe88b8d0a1d6adec5a71d1f6eae034b99a0a0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/sbx-templates@sha256:910e592c4e5049f38478a8ccc38374393eb453d91a767cd32cae637535ab8bf9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/sbx-templates@sha256:ff914fa48aff68aa75f4b60cb83b0c15dab110667df6a9551405d81ba0aa084b